I read security the way an attacker reads it: follow the incentives, find where it breaks. In compliance, the incentives point one way. Almost every guide you'll find is written by a company that sells audits, compliance software or consulting, and the advice bends toward the product.
This section is the other kind. It's written for the team I see most often in 2026: a handful of people who call the OpenAI or Claude API, run on Supabase, Vercel or Lovable, and have just been asked for a SOC 2 report or a forty-page questionnaire. Every figure here was read on the source's own page, dated, and labelled with who published it. For transparency: aliteq runs on Supabase and Cloudflare, was built with AI coding tools, and has no SOC 2 report of its own.
Which frameworks you'll actually be asked for
Most small companies meet these in the same order: a customer's security questionnaire first, then a request for a SOC 2 report, then a data processing agreement if they're in Europe, and a HIPAA business associate agreement if health data is involved. The EU AI Act and NIS2 arrive through contract clauses, not audits.
What each one is, and who asks
SOC 2 Type 1
- Required by law?
- No, voluntary
- Who typically asks
- US enterprise security and procurement teams
- First-year cost (USD)
- Audit fee $10k–$35k (specialist firm)
- Time to have it
- 3–6 months
SOC 2 Type 2
- Required by law?
- No, voluntary
- Who typically asks
- The same buyers, especially at renewal
- First-year cost (USD)
- Audit $15.5k–$50k; all-in ~$20k–$80k (vendor estimates)
- Time to have it
- 6–12+ months
ISO 27001
- Required by law?
- No, voluntary
- Who typically asks
- Often EU, UK and APAC buyers
- First-year cost (USD)
- ~$6.6k–$66k overall (converted from £5k–£50k)
- Time to have it
- About 6 months
HIPAA BAA
- Required by law?
- Yes, if you handle health data for a covered entity
- Who typically asks
- US healthcare providers and plans
- First-year cost (USD)
- Readiness $25k–$100k+ (vendor-reported)
- Time to have it
- Before any health data flows
GDPR DPA
- Required by law?
- Yes, if you process EU personal data for customers
- Who typically asks
- EU customers
- First-year cost (USD)
- No published range
- Time to have it
- Before any personal data flows
NIS2
- Required by law?
- Directly only for medium or larger firms in listed sectors
- Who typically asks
- In-scope EU customers, via supplier clauses
- First-year cost (USD)
- No per-company figure we could verify
- Time to have it
- In force; Denmark since 1 Jul 2025
EU AI Act
- Required by law?
- Yes, where you provide or deploy AI in the EU
- Who typically asks
- EU customers deploying your AI feature
- First-year cost (USD)
- No published range
- Time to have it
- Transparency applies since Aug 2026
Pen test
- Required by law?
- No
- Who typically asks
- Enterprise buyers; auditors accept it as evidence
- First-year cost (USD)
- Typically $5k–$15k
- Time to have it
- Weeks
Two things are worth knowing up front. First, no survey tells you which of these your particular buyer will ask for. The confident percentages you'll see quoted ("80% of enterprises require SOC 2") have no primary source I could find, so I don't repeat them. Ask the buyer. Second, the questionnaire usually comes before any of it: large-company surveys by the vendor Whistic found companies field dozens of security assessments a month, and a small team can answer most of one honestly before it holds any certificate.
What each one costs in year one
A first SOC 2 is the biggest line for most AI startups: compliance vendors put it at about $20,000–$80,000 all-in, with a specialist firm's Type 2 audit fee at $15,500–$50,000. ISO 27001 runs about $6,600–$66,000 overall. GDPR, NIS2 and the AI Act have no price tag: they cost you the work of meeting them.

Read these ranges knowing who wrote them. The SOC 2 figures come mainly from SOC2Auditors.org, an ad-supported directory of audit firms, and from platform vendors such as Drata. The ISO 27001 range is a UK consultancy's, converted from pounds. The HIPAA figure is from Secureframe, which sells HIPAA compliance. For SOC 2 in detail, including an estimator that builds your own number line by line, see SOC 2 for AI startups.
If your product uses AI, the audit-firm A-LIGN's 2026 benchmark is the useful context: of 1,043 companies surveyed, 80% of those using AI said customers ask them risk questions about it, and a third had no AI compliance strategy.
How long until you have something to show
A SOC 2 Type 1 takes about three to six months, and a first Type 2 six to twelve months or more, because its observation window has to pass. ISO 27001 takes around six months to a first certificate. HIPAA and GDPR have no certificate to wait for: the agreement has to be signed before the data flows.
That makes the order of work simple. Sign the agreements the law requires first, answer the questionnaire in front of you honestly, and start the longest clock, the Type 2 window, as early as a real deal justifies.
The EU calendar you're already on
The EU AI Act applies generally since 2 August 2026, including the transparency duty to tell people they're talking to an AI. Its high-risk rules were moved by Regulation (EU) 2026/1744 to 2 December 2027 and 2 August 2028. GDPR has applied since 2018, and Denmark's NIS2 law since July 2025.

Three things on that calendar trip small companies up:
- Pages still claiming high-risk AI rules start in August 2026 are out of date. Regulation (EU) 2026/1744 moved them. What applies to a typical chatbot or generation feature today is Article 50 transparency, and generative systems already on the market before 2 August 2026 have until 2 December 2026 to mark their output.
- NIS2 can reach you even if you're small. It applies directly only to medium-sized or larger companies in listed sectors, but Article 21 obliges those companies to secure their supply chain, so their supplier questionnaires and contract clauses land on you. Denmark's agency, SAMSIK, says the same about out-of-scope suppliers.
- EU–US data transfers rest on a framework under appeal. The EU–US Data Privacy Framework is in force, and an appeal against it (case C-703/25 P) was lodged in October 2025. As of September 2026 I found no ruling. Standard contractual clauses remain the fallback.
What the fines look like
The caps are large: up to €35 million or 7% of turnover for the AI Act's prohibited practices, €20 million or 4% under GDPR, and €10 million or 2% for NIS2's essential entities. Real fines are usually far lower. One break for small companies: AI Act fines for SMEs are capped at the lower of the two amounts.

Fix these before any audit
An auditor, a questionnaire and an attacker all start in the same place: who can reach which data, and where your keys live. For an app built with AI tools, these fixes come first, and every one of them is free:
- Access control on every table. Row Level Security, explained and the difference between login and access control.
- Keys out of the browser. Which API keys in your frontend actually matter, whether an exposed Supabase anon key is a problem, and where secrets belong.
- Backups you've actually restored. Backups, and losing everything.
- The six checks before you share an app, in one checklist, with tool-specific versions for Lovable and the other builders.
The full sequence, lesson by lesson, is the Ship safely track.






